Show filters
20 Total Results
Displaying 11-20 of 20
Sort by:
Attacker Value
Unknown

CVE-2022-3494

Disclosure Date: November 07, 2022 (last updated December 22, 2024)
The Complianz WordPress plugin before 6.3.4, and Complianz Premium WordPress plugin before 6.3.6 allow a translators to inject arbitrary SQL through an unsanitized translation. SQL can be injected through an infected translation file, or by a user with a translator role through translation plugins such as Loco Translate or WPML.
Attacker Value
Unknown

CVE-2022-0193

Disclosure Date: February 14, 2022 (last updated February 23, 2025)
The Complianz WordPress plugin before 6.0.0 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
Attacker Value
Unknown

CVE-2017-10862

Disclosure Date: October 12, 2017 (last updated November 26, 2024)
jwt-scala 1.2.2 and earlier fails to verify token signatures correctly which may lead to an attacker being able to pass specially crafted JWT data as a correctly signed token.
0
Attacker Value
Unknown

CVE-2011-2180

Disclosure Date: June 29, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in dereferer.php in A Really Simple Chat (ARSC) 3.3-rc2 allows remote attackers to inject arbitrary web script or HTML via the arsc_link parameter.
0
Attacker Value
Unknown

CVE-2011-2470

Disclosure Date: June 29, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in chat/base/admin/login.php in A Really Simple Chat (ARSC) 3.3-rc2 allows remote attackers to inject arbitrary web script or HTML via the arsc_message parameter.
0
Attacker Value
Unknown

CVE-2011-2181

Disclosure Date: June 29, 2011 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in A Really Simple Chat (ARSC) 3.3-rc2 allow remote attackers to execute arbitrary SQL commands via the (1) arsc_user parameter to base/admin/edit_user.php, (2) arsc_layout_id parameter in base/admin/edit_layout.php, or (3) arsc_room parameter to base/admin/edit_room.php.
0
Attacker Value
Unknown

CVE-2007-5953

Disclosure Date: November 14, 2007 (last updated October 04, 2023)
Unspecified vulnerability in Really Simple CalDAV Store (RSCDS) before 0.9.0 allows attackers to obtain sensitive information via unspecified vectors.
0
Attacker Value
Unknown

CVE-2007-1982

Disclosure Date: April 12, 2007 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in Really Simple PHP and Ajax (RSPA) 2007-03-23 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) __IncludeFilePHPClass, (2) __ClassPath, and (3) __class parameters to (a) rspa/framework/Controller_v5.php, and (b) rspa/framework/Controller_v4.php.
0
Attacker Value
Unknown

CVE-2007-1851

Disclosure Date: April 03, 2007 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in Really Simple PHP and Ajax (RSPA) 2007-03-23 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the __class parameter to (1) Controller_v4.php or (2) Controller_v5.php.
0
Attacker Value
Unknown

CVE-2002-0463

Disclosure Date: August 12, 2002 (last updated February 22, 2025)
home.php in ARSC (Really Simple Chat) 1.0.1 and earlier allows remote attackers to determine the full pathname of the web server via an invalid language in the arsc_language parameter, which leaks the pathname in an error message.
0